CVE-2013-0247
OpenStack Keystone Essex/Folsom/Grizzly DoS via Invalid Token Request Logging
Title source: llmDescription
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
References (6)
Core 6
Core References
Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=906171
Third Party Advisory x_refsource_confirm
https://bugs.launchpad.net/keystone/+bug/1098307
Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098906.html
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0253.html
Third Party Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1715-1
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/57747
Scores
EPSS
0.0296
EPSS Percentile
86.7%
Details
CWE
CWE-399
Status
published
Products (3)
canonical/ubuntu_linux
12.04
canonical/ubuntu_linux
12.10
openstack/keystone
2012.1 - 2012.1.3
Published
Feb 24, 2013
Tracked Since
Feb 18, 2026